Re: Again: Pix VPN & Routing



Hi,

Routing of traffic on the pix adheres to the routes found in the routing
table.
So if you'd like traffic to certain networks to go out the inside interface,
add routes for these nets to the routing table.
As far as I know there is no option to route based on source address on the
PIX. (as to policy routing on IOS).

Erik


"Christoph Gartmann" <gartmann@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:df156k$l9h$1@xxxxxxxxxxxxxxxxx
> In article <11h7u0vc34pnq40@xxxxxxxxxxxxxxxxxx>, "Megane"
> <debergjesREMOVETHIS@xxxxxxxxxxx> writes:
>>isakmp nat-traversal 20
>>
>
> This helped partially. Now Road-Warrior is able to reach hosts in the LAN
> or
> those nets that have a dedicated route towards inside. But still traffic
> from
> Road-Warrior to hosts that are not part of our LAN go directly through the
> outside interface and not through the inside interface.
>
> Thus is there a way for some sort of policy routing in the Pix, e.g.
> everything
> originating from address 10.1.5.79 (= addresses from the local pool)
> should be
> routed towards the inside interface?
>
> Regards,
> Christoph Gartmann
>
> --
> Max-Planck-Institut fuer Phone : +49-761-5108-464 Fax: -452
> Immunbiologie
> Postfach 1169 Internet: gartmann@immunbio dot mpg dot de
> D-79011 Freiburg, Germany
> http://www.immunbio.mpg.de/home/menue.html


.



Relevant Pages

  • iptables and static routing..
    ... using iptables command. ... Note that if I turn the interface to the network down, ... but also sets unwanted/undesirable routing paths in the routing table. ... should not set the default routes in the first place. ...
    (Fedora)
  • Re: Q: multi-homed server with multiple default routers
    ... Instead only the destination address and routing table are used ... >> to determine the interface and hardware destination. ... to add a permanent route other than adding a default router. ... It is also a method to add one or more permanent routes that are not ...
    (comp.unix.solaris)
  • Re: dymanic route table problem
    ... The redirect has been mentioned by another person as well and that is surely what it seems like it is happening. ... gateway is pointed at the PIX, the PIX is responsible - it may not be doing ... router's routing table, ... it will learn direct routes to hosts via an ip redirect. ...
    (microsoft.public.win2000.networking)
  • Re: [fw-wiz] Multiple routes out
    ... Your natting will detrmine your routing. ... routes for the other nets ... anything coming in to the ASA on InsideNet1 needs to be given ... Anything coming in on InsideNet2 needs to be given to OutsideNet2 interface ...
    (Firewall-Wizards)
  • Re: Multipath routing - failover version
    ... IP to an interface if the route already exists. ... If machine you add the IP to the vlan on ... Obviously, also, a machine should prefer it's own interface routes to routes ... provided by external routing protocols. ...
    (freebsd-hackers)